The folks at SektionEins security consulting are starting a new Month of PHP Security. They are currently collecting interesting entries via a public CfP on php-security.org and will publish the most interesting stuff during
May 2010 - one item per day.
Papers, Exploits and other stuff related to the following topics can be submitted:
- New vulnerability in PHP itself
- New vulnerability in PHP extensions/patches (such as eAccelerator or Suhosin
)
- Explain a single topic of PHP application security in a detailed paper
- Explain a complex vulnerability in/attack against an “interesting” PHP application
- Explain a complex attack method (in a theoretical article) against PHP itself
- Explain how to attack encrypted PHP applications
- Release of a new open source PHP security tool
- Other stuff related to PHP security
There’s a bunch of prices, including security conference tickets and Amazon vouchers. You should check it out!
More info:
http://www.php-security.org/